Files
compiler-explorer/lib/app/server.ts
Matt Godbolt (bot acct) 07226d33bf Reapply extraBodyClass-driven branding, validating via the manifest in production (#8935)
Reapplies #8755, which was reverted in 463e3e70f after it broke the
staging deploy:

```
error: Top-level error (shutting down): Missing branding assets for extraBodyClass='staging'
in /infra/.deploy/static: favicon-staging.ico, site-logo-staging.svg
```

### What went wrong

`validateBrandingAssets` checked `staticPath` on the local filesystem.
That's correct for dev and local prod runs, but AWS deploys ship **two**
packages (`build-dist.sh`): the node app tarball (no `static/` at all)
and the static bundle, which goes to the CDN
(`staticUrl=https://static.ce-cdn.net/`). Production nodes never have
the branding files on disk, so any env with `extraBodyClass` set
(staging, beta, win\*) died at startup. Prod itself has an empty
`extraBodyClass`, which is why the check short-circuited there and the
bug only surfaced on the staging deploy.

### The fix (second commit)

The webpack manifest **does** ship with the node app, and lists every
asset copied from `public/` into the static bundle. So in production,
validate the derived `favicon-<class>.ico` / `site-logo-<class>.svg`
names against **manifest keys** instead of the filesystem; dev keeps the
on-disk check against `public/`. This preserves the fail-fast-on-typo
behaviour #8755 wanted, checking the thing that actually describes what
shipped to the CDN. If the manifest can't be loaded we're already on the
existing warn-and-fall-back handler, so validation is skipped rather
than fatal.

`setupStaticMiddleware` now takes the parsed manifest (loaded once in
`setupWebServer` via new `loadStaticManifest`) instead of reading it
itself.

### Verification

- Fresh **production** webpack build: all six env asset pairs (dev,
beta, staging, winprod, winstaging, wintest) appear as plain-name keys
in `manifest.json` (the win\* symlink placeholders are dereferenced on
copy).
- Booted the built `out/dist` server code in the exact deploy layout
(`staticUrl` set, nonexistent `staticPath`, `extraBodyClass=staging`):
boots cleanly and renders `favicon-staging.ico` +
`site-logo-staging.svg`; a mistyped class still fails startup with a
clear error.
- New regression tests pin both behaviours at the `setupWebServer` level
with a shipped-manifest-only layout.

⚠️ Merge timing: prod's empty `extraBodyClass` never exercises this path
— the real test is the next **staging** deploy, so this should merge
when someone (me) is ready to deploy staging and watch it.

cc @partouf — sorry again for the breakage; this validates against the
manifest rather than expecting the CDN bundle's files on local disk.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: mattgodbolt-molty <mattgodbolt-molty@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-20 21:37:49 +01:00

114 lines
4.3 KiB
TypeScript

// Copyright (c) 2025, Compiler Explorer Authors
// All rights reserved.
//
// Redistribution and use in source and binary forms, with or without
// modification, are permitted provided that the following conditions are met:
//
// * Redistributions of source code must retain the above copyright notice,
// this list of conditions and the following disclaimer.
// * Redistributions in binary form must reproduce the above copyright
// notice, this list of conditions and the following disclaimer in the
// documentation and/or other materials provided with the distribution.
//
// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
// AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
// IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
// ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE
// LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
// CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
// SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
// INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
// CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
// ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
// POSSIBILITY OF SUCH DAMAGE.
import express from 'express';
import type {AppArguments} from '../app.interfaces.js';
import {logger} from '../logger.js';
import {createRenderHandlers} from './rendering.js';
import {ServerDependencies, ServerOptions, WebServerResult} from './server.interfaces.js';
import {setupBaseServerConfig, setupBasicRoutes, setupLoggingMiddleware} from './server-config.js';
import {
getBrandingPublicDir,
loadStaticManifest,
setupStaticMiddleware,
setupWebPackDevMiddleware,
validateBrandingAssetsInManifest,
validateBrandingAssetsOnDisk,
} from './static-assets.js';
export {startListening} from './server-listening.js';
export {isMobileViewer} from './url-handlers.js';
/**
* Configure a web server and its routes
* @param appArgs - Application arguments
* @param options - Server options
* @param dependencies - Server dependencies
* @returns Web server configuration
*/
export async function setupWebServer(
appArgs: AppArguments,
options: ServerOptions,
dependencies: ServerDependencies,
): Promise<WebServerResult> {
const webServer = express();
const router = express.Router();
let pugRequireHandler;
let staticManifest: Record<string, string> | undefined;
try {
if (appArgs.devMode) {
pugRequireHandler = await setupWebPackDevMiddleware(options, router);
} else {
staticManifest = await loadStaticManifest(options.manifestPath);
pugRequireHandler = setupStaticMiddleware(options, router, staticManifest);
}
} catch (err: unknown) {
const error = err as Error;
logger.warn(`Error setting up static middleware: ${error.message}`);
pugRequireHandler = path => `${options.staticRoot}/${path}`;
}
// Deliberately fatal (and outside the try above): a mistyped extraBodyClass should stop
// startup, not serve broken branding. If the manifest failed to load we're already limping
// on the fallback handler, so there's nothing to validate against and we don't try.
if (appArgs.devMode) {
await validateBrandingAssetsOnDisk(getBrandingPublicDir(), options.extraBodyClass);
} else if (staticManifest) {
validateBrandingAssetsInManifest(staticManifest, options.extraBodyClass);
}
const {renderConfig, renderGoldenLayout, embeddedHandler} = createRenderHandlers(
pugRequireHandler,
options,
dependencies,
);
// Add healthcheck before logging middleware to prevent excessive log entries
webServer.use(dependencies.healthcheckController.createRouter());
setupBaseServerConfig(options, renderConfig, webServer, router);
setupLoggingMiddleware(appArgs.devMode, router);
setupBasicRoutes(
router,
renderConfig,
embeddedHandler,
dependencies.ceProps,
dependencies.awsProps,
options,
dependencies.clientOptionsHandler,
);
return {
webServer,
router,
pugRequireHandler,
renderConfig,
renderGoldenLayout,
};
}